Security

gatts87
gatts87 Posts: 61 Arc User
edited January 2009 in General Discussion
I'm new to this game so not really sure what the answer may be, but anyways... What's the security(if any) for this game? I'd like to think that my gear/etc is protected from hackers and other things as long as I don't do anything ****(like give out my account info/etc).
Post edited by gatts87 on

Comments

  • Drazo - Heavens Tear
    Drazo - Heavens Tear Posts: 947 Arc User
    edited January 2009
    Security on the password protection side is mostly your responsabilty. Here's a few personal tips on how to never be ****:

    1. Don't tell anyone, anywhere, your password or give hints to what it could be.
    2. Remember your password well, don't write it down anywhere.
    3. Keep up to date anti-malware software (I suggest use at least 2 different ones) and scan regularly for keyloggers and middle-man attacks (packet sniffers and modifiers), etc. The use of a firewall is strongly recommened.
    4. Don't use really short or easy to guess passwords.
    5. Do not lend your account to anyone, besides you can be banned for doing so.

    That's about it really. Don't worry about hackers breaking into the database, because not only is this being ran by a professional organisation but it's their sole responsablity to keep it well protected and almost everyone with any sense at all encrypts passwords and other sensitive data with a one-way algorithm, as the hash cannot be reversed.

    b:victory
    Non-mule alts:

    Drazo - Venomancer - Dreamweaver - Semi-active
    Knatami - Barbarian - Heavens Tear - Inactive
    Drazorus - Archer - Sanctuary - Inactive
    Cidemami - Cleric - Dreamweaver - Inactive
    Recilsami - Blademaster - Heavens Tear - Inactive
    DrazoThePsy - Psychic - Dreamweaver - Active
    DrazoTheSas - Assassin - Dreamweaver - Active
  • Taiyed - Heavens Tear
    Taiyed - Heavens Tear Posts: 7 Arc User
    edited January 2009
    and yet logging into the website with your account info is done through http and not https. The only way to get a valid certificate is if you click on charge up at the top...
  • Ormenelle - Heavens Tear
    Ormenelle - Heavens Tear Posts: 47 Arc User
    edited January 2009
    Absolutely.

    Plus, the fact that the avatars reflect class and level of our characters proves that the forums server has a set of routines directly accessing the game's database. If I were to **** PWI I would target the forums to put my hands on those subroutines so as to boost chars [ free levels and coins ] then resell them on some sort of Game eBay or another.

    Let's just hope PWi has real firewalls, use encryption and didn't touch anything branded Symantec even with a ten foot pole.

    Note, you can put a code on your bank too, to add another layer of security, and it's a good idea.
  • Taiyed - Heavens Tear
    Taiyed - Heavens Tear Posts: 7 Arc User
    edited January 2009
    Hell you wouldn't even need to go that far. Wont go into details, but college networks and bind can be a bad thing. Regardless, anything that requires us to put in our account details should be https minimum, but if the cert you have on the charge portal is an older one you better hope someone doesn't have access to a buncha ps3's and knows what they're doing b:shutup